Applies the gen2 desktop-PTT review summary
(`gen2/chanora-desktop-ptt-review-summary-v0.9.2.md`) to our doc set
with the owner rulings PTT-OPEN-001 through PTT-OPEN-006 resolved as
accepted decisions DEC-023 through DEC-028:
* DEC-023 Windows Global PTT P0 / MVP
* DEC-024 macOS Global PTT P0 / MVP with permission UX
* DEC-025 Linux officially-tested env: GNOME on Wayland only
* DEC-026 Mouse side buttons supported (Win + macOS; Linux portal)
* DEC-027 PTT diagnostics: capability + availability only, no
raw key codes ever
* DEC-028 Missed-key-up watchdog: P0
Requirements (SysRS / SRS) and architecture (SysDes / SAD / SDD)
gain the desktop-PTT ID set the gen2 summary describes:
SysRS-296..302 -> SysDes-142..148
-> SRS-195..203
-> SAD-071..079
-> SDD-081..092
ID totals advance from 295 / 141 / 194 / 70 / 80 to 302 / 148 / 203
/ 79 / 92. The strict layered sourcing rule (`SRS -> SysDes` only,
`SAD -> SRS` only, `SDD -> SAD` only) is preserved; the
`tools/validate_docs.py` validator reports zero undefined refs and
zero direct-layer-rule violations.
New document:
* `docs/architecture/desktop-ptt-architecture.md` — capability
ladder (L0Focused, L1GlobalShortcut, L2GlobalHoldToTalk,
L3GlobalWithMouseButtons, L4DeviceAware reserved), Windows /
macOS / Linux strategies, privacy rule, audio-gate rule,
missed-key-up watchdog, release-readiness evidence requirement,
traceability summary.
Doc addenda (Baseline Candidate 0.9.3):
* `privacy/privacy-policy.md` — no raw key history, capability-
dependent Global PTT, UI reflects actual runtime capability
* `security/threat-model.md` — THREAT-PTT-001..006
* `security/diagnostic-redaction-audit-report.md` —
REDACT-PTT-001..006 banned field list enforced by `PttSanitizer`
* `release/platform-release-policy.md` — per-platform evidence
fields, no over-claim on untested Linux compositors
* `release/release-readiness-go-nogo-record.md` — RR-PTT-001..008
release-readiness items
* `verification/swe4-unit-verification-plan.md` —
SWE4-UV-035..039
* `verification/swe5-software-integration-verification-plan.md` —
SWE5-IV-015
* `verification/swe6-software-verification-plan.md` — SWE6-SV-017
* `verification/sys4-system-integration-verification-plan.md` —
SYS4-SIV-016
* `governance/traceability-matrix.md` — full PTT trace rows +
verification map
* `governance/decision-impact-assessment.md` — DEC-023..028
impact matrix
* `governance/product-decision-register.md` v0.9.9 entry
recording DEC-023..028 in the decision table and the status
table at §7
* `governance/document-index.md` — adds
`desktop-ptt-architecture.md` to the controlled set
* `architecture/proof-of-concept-plan.md` —
PoC-PTT-001..005 platform items
* `references/external-references.md` — Windows Raw Input,
macOS event-tap, Linux GlobalShortcuts portal references
* Both validation reports
(`baseline-candidate-validation-report.md`,
`repo-format-validation-report.md`) bumped to v0.9.3 with the
new ID totals (302 / 148 / 203 / 79 / 92).
README §"Desktop Push-to-Talk" added between Architecture Overview
and Repository Layout: capability levels, per-platform strategy,
privacy posture, missed-key-up watchdog.
Tooling:
* `tools/validate_docs.py` copied from the gen2 zip into the
repo tree (was previously available only inside the zip).
Reports zero undefined refs, zero direct-layer-rule violations,
English-only CJK check passes. The 35 "old package-style
filename" hits are pre-existing and identical to the gen2
baseline (they live in `path-migration-map.md` and config-ID
headers of governance docs and are intentional per the path
migration policy).
* `.gitignore` adds `/gen2/` so the externally-provided review
package does not enter the repo.
No code changes in this commit; B (the implementation split into
`transmit_active` / `capture_active`, `PttCapabilityLevel`
reporting, `PttSanitizer` diagnostics rule, and the UI capability
badge) follows in a separate commit.
155 lines
9.9 KiB
Markdown
155 lines
9.9 KiB
Markdown
# Sec Threat Model V0.9.2.2.1
|
|
|
|
**Document type:** Security / Threat Model
|
|
**Version:** 0.9.2
|
|
**Status:** Baseline Candidate
|
|
**Language:** English
|
|
**Product:** Chanora
|
|
**Repo path:** `docs/security/threat-model.md` ---
|
|
|
|
## 1. Purpose
|
|
|
|
This document identifies Chanora security assets, trust boundaries, attack surfaces, threat scenarios, mitigations, and residual risks.
|
|
|
|
This document must be completed and approved before public or external release.
|
|
|
|
## 2. Security Scope
|
|
|
|
In scope:
|
|
|
|
- Identity private keys and identity material
|
|
- Server passwords
|
|
- Saved bookmarks and recent server entries
|
|
- Local database
|
|
- Secure storage
|
|
- Diagnostic logs and export bundles
|
|
- Protocol input from compatible servers
|
|
- Text messages, channel names, server names, and nicknames
|
|
- Audio device access and microphone permission
|
|
- Platform permission flows
|
|
- Dependency and supply-chain risks
|
|
- Flutter/Rust bridge boundary
|
|
- Local file export/import surfaces
|
|
|
|
Out of scope unless later added:
|
|
|
|
- Cloud account sync
|
|
- Server hosting infrastructure operated by Chanora
|
|
- Telemetry backend
|
|
- Crash reporting backend
|
|
- Payment processing
|
|
|
|
## 3. Assets
|
|
|
|
| Asset ID | Asset | Sensitivity | Required protection |
|
|
|---|---|---|---|
|
|
| SEC-ASSET-001 | Identity private key / identity secret | Critical | Store only in platform secure storage; never log. |
|
|
| SEC-ASSET-002 | Server password | Critical | Store only in platform secure storage; redact from diagnostics. |
|
|
| SEC-ASSET-003 | Server address / bookmark | Sensitive | Store locally; redact or minimize in diagnostic export. |
|
|
| SEC-ASSET-004 | Nickname / user identity display name | Personal / user-provided | Preserve Unicode; avoid unnecessary upload. |
|
|
| SEC-ASSET-005 | Channel names and server names | Potentially sensitive | Treat as user/server content; redact where configured. |
|
|
| SEC-ASSET-006 | Chat text | Sensitive user/server content | Do not upload automatically; redact from diagnostics by default unless user explicitly includes. |
|
|
| SEC-ASSET-007 | Diagnostic bundle | Sensitive aggregate | Redact secrets; user-initiated export only. |
|
|
| SEC-ASSET-008 | Local database | Sensitive | Protect via OS file permissions; avoid plaintext secrets. |
|
|
| SEC-ASSET-009 | Logs | Sensitive | Redact secrets and avoid verbose sensitive content. |
|
|
| SEC-ASSET-010 | Audio stream | Sensitive real-time data | Do not persist audio unless explicitly designed later. |
|
|
| SEC-ASSET-011 | Dependency graph | Supply-chain-sensitive | Track licenses, vulnerabilities, and source integrity. |
|
|
|
|
## 4. Trust Boundaries
|
|
|
|
| Boundary ID | Boundary | Risk |
|
|
|---|---|---|
|
|
| TB-001 | User input to Flutter UI | Malformed or hostile input. |
|
|
| TB-002 | Flutter to Rust bridge | DTO validation and error mapping required. |
|
|
| TB-003 | Rust Core to protocol adapter | Protocol events and external inputs must be normalized. |
|
|
| TB-004 | Protocol adapter to external compatible server | Untrusted network/server input. |
|
|
| TB-005 | Rust/Flutter to platform secure storage | Platform-specific failure modes. |
|
|
| TB-006 | App to local database/file system | File tampering, data leakage, permissions. |
|
|
| TB-007 | Diagnostics export to user-controlled destination | Sensitive data leakage. |
|
|
| TB-008 | Audio device boundary | Permission and device-route privacy. |
|
|
| TB-009 | Dependency supply chain | Vulnerable or malicious dependencies. |
|
|
|
|
## 5. Attack Surfaces
|
|
|
|
| Surface ID | Attack surface | Example threats |
|
|
|---|---|---|
|
|
| AS-001 | Connection form | Credential capture in logs, malformed host input. |
|
|
| AS-002 | Protocol input | Malformed packets, hostile names/messages, state desync. |
|
|
| AS-003 | Bridge DTOs | Invalid commands, unexpected event payloads. |
|
|
| AS-004 | Local database | Tampering, unauthorized read. |
|
|
| AS-005 | Secure storage | Platform fallback failure or incorrect secret classification. |
|
|
| AS-006 | Diagnostics export | Secret leakage, excessive server/user information. |
|
|
| AS-007 | Logs | Password or identity leakage. |
|
|
| AS-008 | Audio permissions | Unclear microphone use or unintended capture. |
|
|
| AS-009 | Dependency ecosystem | Vulnerable packages or license incompatibility. |
|
|
| AS-010 | Store/package distribution | Tampered artifacts or signing issues. |
|
|
|
|
## 6. Threat Scenarios and Mitigations
|
|
|
|
| Threat ID | Scenario | Impact | Mitigation | Verification |
|
|
|---|---|---|---|---|
|
|
| THR-001 | Server password is logged during connection failure. | Credential leakage. | Redaction filters; never log secret fields. | Diagnostic redaction audit. |
|
|
| THR-002 | Identity private key is stored in local DB. | Identity compromise. | Secure storage classification and audit. | Secure storage audit. |
|
|
| THR-003 | Diagnostic export includes server password or identity secret. | Credential leakage. | Export redaction and denylist/allowlist design. | Redaction audit. |
|
|
| THR-004 | Hostile server sends malformed Unicode or extremely long names. | Crash, UI corruption, log injection. | Boundary validation, length limits, safe rendering. | Protocol fuzz/sanitization tests. |
|
|
| THR-005 | Protocol event causes inconsistent UI state. | Wrong user/channel state. | State reducer validation and snapshot recovery. | SWE.5/SWE.6 tests. |
|
|
| THR-006 | Dependency has known critical vulnerability. | Compromise or exploit risk. | Dependency scan and release gate. | Supply-chain report. |
|
|
| THR-007 | OSS license is incompatible with release model. | Legal/compliance risk. | License inventory and legal review. | Dependency/license report. |
|
|
| THR-008 | Microphone permission is unclear to user. | Privacy risk. | Permission explanation and privacy policy. | Privacy/legal review. |
|
|
| THR-009 | Logs contain private channel or nickname data by default. | Privacy leakage. | Minimize logs; redact or hash sensitive content. | Diagnostics audit. |
|
|
| THR-010 | Build artifact is not traceable to commit. | Supply-chain/release integrity risk. | Release record with commit, tag, build number, hashes. | Go/No-Go record. |
|
|
|
|
## 7. Residual Risks
|
|
|
|
| Risk ID | Risk | Disposition |
|
|
|---|---|---|
|
|
| RISK-001 | External compatible servers may expose untrusted content. | Accept with boundary validation and safe rendering. |
|
|
| RISK-002 | Platform secure storage behavior differs by OS/version. | Mitigate with per-platform audit. |
|
|
| RISK-003 | Dependency vulnerabilities may appear after release. | Mitigate with recurring scan and patch policy. |
|
|
| RISK-004 | Diagnostic bundles may contain contextual sensitive data even after redaction. | Mitigate with user confirmation and privacy notice. |
|
|
|
|
## 8. Approval
|
|
|
|
| Role | Name | Decision | Date |
|
|
|---|---|---|---|
|
|
| Security Reviewer | TBD | Pending | TBD |
|
|
| Software Architect | TBD | Pending | TBD |
|
|
| Platform Owner | TBD | Pending | TBD |
|
|
| QA / Verification Owner | TBD | Pending | TBD |
|
|
|
|
## 9. Change History
|
|
|
|
| Version | Date | Description |
|
|
|---|---|---|
|
|
| 0.9.0 | 2026-05-14 | Initial threat model template and baseline candidate. |
|
|
|
|
|
|
## Baseline Candidate 0.9.1 Update
|
|
|
|
| Version | Date | Description |
|
|
|---|---|---|
|
|
| 0.9.1 | 2026-05-14 | Updated baseline after product decision closure: Apple App Store SDK gate uses Xcode 26+ and iOS 26 / iPadOS 26 SDK+ since 2026-04-28, platform baselines and decision traceability propagated across the document set. |
|
|
|
|
|
|
## Baseline Candidate 0.9.2 Update
|
|
|
|
| Version | Date | Description |
|
|
|---|---|---|
|
|
| 0.9.2 | 2026-05-14 | Corrected Apple App Store Connect upload gate to 2026-04-28 and checked full-package naming, references, and coverage. |
|
|
|
|
|
|
## Desktop Push-to-Talk Threat Addendum (Baseline Candidate 0.9.3)
|
|
|
|
| ID | Threat | Asset | Likelihood | Impact | Mitigation |
|
|
|---|---|---|---|---|---|
|
|
| THREAT-PTT-001 | A desktop PTT backend logs raw key codes or scan codes to the in-memory log sink. | User keystroke privacy | Medium (without controls) | High | `PttSanitizer` per SAD-077 / SDD-090 drops records with banned field names before they reach any sink; backend implementations call `AudioTransmitGate::set` only and never log key data. |
|
|
| THREAT-PTT-002 | A desktop PTT backend leaks raw key codes through the user-initiated diagnostic export. | User keystroke privacy | Medium | High | Diagnostic export carries only the capability level, backend identifier, and bound input class per SRS-202 / DEC-027. |
|
|
| THREAT-PTT-003 | The application advertises Global PTT support on a platform / permission / environment where it does not actually work. | Honest release claim | Medium | Medium (UX regression, support load) | `PttCapabilityLevel` is published from the *active* backend only; the UI capability badge reflects runtime measurement (SRS-196 / SysRS-298). Release readiness record carries per-platform evidence per SysDes-148. |
|
|
| THREAT-PTT-004 | A missed key-up event leaves `transmit_active` true after the user releases the binding (for example because the OS suppressed the event while Chanora was minimised). | Voice transmission integrity, user expectation of mute | Medium | Medium | `MissedKeyUpWatchdog` per SAD-079 / SDD-092 self-clears `transmit_active` after a configured timeout (default 30 s); the watchdog timeout is a P0 requirement per DEC-028. |
|
|
| THREAT-PTT-005 | A malicious or buggy third-party application registers a global hook that intercepts Chanora's binding and forces PTT on. | Voice transmission integrity | Low | Medium (user can mitigate by switching binding) | Out of MVP scope; documented as a deferred risk. Chanora reports the active backend identifier so a support investigation can correlate. |
|
|
| THREAT-PTT-006 | macOS Input-Monitoring / Accessibility permission is revoked at runtime; the application continues to claim Global PTT. | Honest capability state | Low | Medium | `MacOSEventTapBackend` re-queries the permission state on each tap-disabled callback and downgrades to `L0Focused` via `BridgeEvent::PttCapability`. |
|
|
|
|
| Version | Date | Description |
|
|
|---|---|---|
|
|
| 0.9.3 | 2026-05-15 | Added desktop PTT threats THREAT-PTT-001..006: raw key logging, key data in diagnostic export, capability over-claim, missed key-up, third-party hook interference, and macOS permission revocation. |
|